Cybersecurity Engineer

Location
Limassol
Workplace
Hybrid

About this role

Location: Limassol, Cyprus (hybrid, occasional travel to Malta)

Department: Information Technology

Reports To: Head of IT Platforms & Security

Type: Full-time


Role Summary

This is a hands-on security engineering role, not a policy-only one. You look after the day-to-day security of Sigma's Microsoft 365 tenant, Cloudflare edge and office and event networks — you configure the controls yourself, watch the alerts, and drive issues through to closure with IT Operations and DevOps.

Roughly 70% technical — configuration, hardening, detection and incident response — and 30% governance — policy, risk, audits and awareness. Fast-moving, multi-site environment.

What you'll work with

  • Microsoft 365 / Entra ID — Defender, Intune, Conditional Access, MFA, DLP
  • Cloudflare — WAF, DNS, Zero Trust access and tunnels
  • Firewalls & networks — Meraki and UniFi across offices and event sites, plus VPN
  • Linux servers — built and patched by our DevOps team; you set and check the security baseline
  • Log360 (SIEM) and Site24x7 (monitoring) — your daily working view
  • Endpoints & SaaS — Windows and macOS fleet, BYOD, NAS, and a broad SaaS estate

You don't need all of these on day one. Strong Microsoft 365 security plus solid networking is the core — we'll get you up to speed on the rest.


What you'll do

  • Microsoft 365 & identity — Harden the M365 security baseline and improve Secure Score. Tune Defender anti-phishing and anti-spam, keep SPF, DKIM and DMARC enforced, maintain Conditional Access and MFA policies, manage Intune device compliance, and clean up risky apps, guest access and stale admin accounts.
  • Cloudflare & edge — Manage WAF rules, DNS hygiene and TLS across our domain portfolio. Move internal services behind Zero Trust access and tunnels instead of exposing them directly. Investigate blocks and false positives with the application owners rather than switching protection off.
  • Firewalls & network — Configure and review firewall rules and VLAN segmentation. Run periodic rule clean-ups — no any/any rules, no forgotten inbound ports — secure Wi-Fi and guest networks, and manage site-to-site and remote-access VPN.
  • Servers & cloud, with DevOps — DevOps builds and patches the Linux estate. You define the security baseline (CIS-aligned), review the estate against it, and track what needs fixing to closure. You should be comfortable on the command line reading logs and checking configuration — you don't need to be a Linux sysadmin. Same for our cloud footprint: review IAM, security groups, logging and encryption.
  • Vulnerability management — Run regular authenticated scans, prioritise findings by real risk rather than forwarding raw reports, assign owners, verify the fixes, and coordinate external penetration tests and the remediation that follows.
  • Monitoring & incident response — Own the security side of Log360: onboard log sources, build and tune correlation rules, and cut the noise so alerts are trusted. Be first responder for security incidents — investigate, contain, recover, communicate clearly to management, then write it up and fix the root cause.
  • Governance — Keep the security policy set current and matched to how systems are actually configured. Maintain the risk register mapped to ISO 27001, NIST CSF and CIS Controls, support audits and GDPR obligations, review new SaaS vendors, and run awareness training and phishing simulations.
  • Reporting — A short monthly security posture report and a rolling security roadmap, explained to management in plain language.



What we're looking for

  • 3+ years hands-on in security, security engineering, or security-focused IT infrastructure
  • Real administration experience with Microsoft 365 security — Defender, Entra ID, Conditional Access, Intune
  • Solid firewall and network security — rule design and review, segmentation, VPN, wireless (Meraki, UniFi, Fortinet, pfSense or similar)
  • Comfortable on the Linux command line: read logs, check services, review configuration
  • Some experience with a SIEM or central log platform — Log360, Sentinel, Wazuh, Splunk or ELK; any of them transfers
  • Incident response basics: you've worked a phishing case, a compromised account or a suspicious endpoint
  • Working understanding of ISO 27001, NIST CSF or CIS Controls and how to apply them
  • Clear written and spoken English, and the ability to explain risk to non-technical people



Nice to have

  • Cloudflare or another edge / Zero Trust platform · scripting and automation (PowerShell, Microsoft Graph, Python, Bash) · AWS or Azure security · vulnerability scanners (Nessus, Qualys, OpenVAS) · penetration testing exposure and OWASP Top 10 · container and CI/CD security awareness · distributed, multi-office or event environments · iGaming, fintech or another regulated sector.
  • Certifications — welcome, never a requirement: Security+, CySA+, SC-200, SC-300, ISO 27001 Lead Implementer or Auditor, OSCP, CEH, CISSP, CISM.



Your first 90 days

  • Review the Microsoft 365 security baseline and deliver a prioritised hardening plan
  • Audit Cloudflare and DNS across our domains and close off anything exposed
  • Review firewall rules and network segmentation across all sites
  • Agree a CIS-aligned Linux hardening baseline with DevOps and assess the estate against it
  • Close the gaps in Log360 log coverage and tune out the noise
  • Deliver the first full vulnerability scan cycle with a tracked remediation plan



Tired of cold applications?

Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.

Know someone who'd be great for this?